Input validation error in Open vSwitch - CVE-2020-35498
Published: February 10, 2021 / Updated: April 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing network packets. A remote attacker can send specially crafted traffic to the system and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
SUSE Linux Enterprise Server
Ubuntu
openEuler
Fedora
openvswitch (Red Hat package)
openvswitch (Debian package)
ovn2.11 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.13 (Red Hat package)
openvswitch-common (Ubuntu package)
libopenvswitch-2_11-0
openvswitch-debugsource
openvswitch-debuginfo
openvswitch
libopenvswitch-2_11-0-debuginfo
openvswitch-help
openvswitch-devel
net-misc/openvswitch
dpdk
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-35498
openvswitch (Debian package) - update to 2.10.7+ds1-0+deb10u1
ovn2.11 (Red Hat package) - update to 2.11.1-57.el7fdp
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-83.el8fdp, 2.11.3-86.el7fdp
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-79.5.el8fdp, 2.13.0-81.el7fdp
openvswitch-common (Ubuntu package) - addressed in versions 2.5.9-0ubuntu0.16.04.3, 2.9.8-0ubuntu0.18.04.2, 2.13.1-0ubuntu0.20.04.4, 2.13.1-0ubuntu1.3
libopenvswitch-2_11-0 - update to 2.11.5-3.9.1
openvswitch-debugsource - update to 2.11.5-3.9.1
openvswitch-debuginfo - update to 2.11.5-3.9.1
openvswitch - update to 2.11.5-3.9.1
libopenvswitch-2_11-0-debuginfo - update to 2.11.5-3.9.1
openvswitch - update to 2.12.0-11
openvswitch-help - update to 2.12.0-11
openvswitch-devel - update to 2.12.0-11
openvswitch-debuginfo - update to 2.12.0-11
openvswitch-debugsource - update to 2.12.0-11
openvswitch - update to 2.15.0-1.fc33
net-misc/openvswitch - update to 2.17.6
Red Hat OpenShift Container Platform - update to 4.7.4
dpdk - update to 20.11-1.fc33
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Denial of service in Open vSwitch
- Red Hat Enterprise Linux 8 update for openvswitch2.13
- Debian update for openvswitch
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.11
- Red Hat Enterprise Linux Fast Datapath update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.11
- Multiple vulnerabilities in Red Hat Virtualization
- Red Hat Enterprise Linux Fast Datapath update for openvswitch
- Red Hat OpenStack Platform 13.0 update for openvswitch2.11
- Ubuntu update for openvswitch
- SUSE update for openvswitch
- Gentoo update for Open vSwitch
- openEuler 20.03 LTS SP1 update for openvswitch
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Fedora 33 update for dpdk, openvswitch